Re: what is that best way to install program?

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 09/27/05


Date: Mon, 26 Sep 2005 21:00:32 -0500

You are correct in your concern about using a domain admin account. In my
opinion a domain administrator should never logon to a domain computer that
is not a known secure admin workstation. What you can do is to add a regular
domain user account to the local administrators group on any domain
computer. Then you can logon with that account which would have no special
powers in the domain assuming you do NOT use the same password as you do for
your domain administrator account which again could be used to try and
compromise a domain administrator account as attackers know that users
commonly use the same password for all their user accounts. You can use a
Group Policy "startup" script using the net localgroup command to add a
global group to the local administrators group on domain computers or use
Group Policy Restricted Groups at the Organizational Unit level and the
"member of " [ for W2K SP4] option to add a global group to the local
administrators group on domain computers in that OU. I would also use a
separate global group to manage servers and other critical computers in case
your local administrator password is captured so that it could not be used
on those sensitive computers. The link below explains more about Restricted
Groups. FYI for .msi software packages you can publish them for
users/computers via Group Policy Software Installation to make authorized
software available to domain users that can be installed without the
intervention of an administrator. --- Steve

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

"James Pang" <news.microsoft.com> wrote in message
news:uqJ5gRwwFHA.3860@TK2MSFTNGP09.phx.gbl...
> we have a small domain, and two system administrator. what we used to do
> is when user call us and say they want a software we go and install it
> with domain admin account. But MS hacker could install a Trojan and
> capture the admin password. so waht is the best do that?
>
> --
> Tech Servant James Pang.
>



Relevant Pages

  • Re: Enabling an audit trail for Administrator Functions
    ... We have 2 accounts, a normal domain user and a domain admin account for all administrative tasks. ... "Administrator" did this or did that and not knowing what employee did ...
    (microsoft.public.windows.server.active_directory)
  • Insufficient rights to run system restore
    ... XP and 2000 Professional have the security built into ... >administrator and try again. ... account, or a domain ... >If I log on using the domain admin account then I have ...
    (microsoft.public.windowsxp.general)
  • Client Push Installation - URGENT REQUEST
    ... I do not have any domain admin account to all the client machine due to ... administrator password. ... When I select Winodws User account in the Client Push Installation ...
    (microsoft.public.sms.setup)
  • Insufficient rights to run system restore
    ... to run system restore, saying ... administrator and try again. ... We get this using either the local administrator account, ... If I log on using the domain admin account then I have no problems. ...
    (microsoft.public.windowsxp.general)
  • Re: Event 1202 Warnings after Renaming Administrator Acct on SBS2003
    ... policy to rename the account although it is not really necessary or useful. ... Did I check Group Policies for references to the Administrator ... Failed to perform redirection of folder Desktop. ...
    (microsoft.public.windows.server.general)